mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Zhang, Yidong (David)" <yidong.zhang@amd.com>
To: Lizhi Hou <lizhi.hou@amd.com>,
	quic_jhugo@quicinc.com, karol.wachowski@linux.intel.com,
	max.zhen@amd.com, ogabbay@kernel.org,
	dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org
Cc: sonal.santan@amd.com, mario.limonciello@amd.com
Subject: Re: [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation
Date: Tue, 29 Sep 2026 17:20:37 -0700	[thread overview]
Message-ID: <906d1899-26af-4829-8a4b-9d451ff13917@amd.com> (raw)
In-Reply-To: <c5da23b0-1552-b601-78e9-602e4140297d@amd.com>


On 9/28/2026 2:06 PM, Lizhi Hou wrote:
>
> On 9/25/26 18:34, David Zhang wrote:
>> This is part of the fix to align BO reservation locking and fence
>> management with aie2.
>>
>> Fences published into BO reservation objects via dma_resv_add_fence()
>> can outlive the hardware context (e.g. when a BO is exported as a
>> dma-buf and imported by another process). Using hwctx->name for the 
>> fence
>> timeline name risks a use-after-free once the hwctx is destroyed.
>> Switch timeline name to dev_name() which is backed by the device that
>> outlives any individual context.
>>
>> Additionally, allocate a unique fence context via
>> dma_fence_context_alloc(1) for each job fence so that 
>> dma_resv_add_fence()
>> does not evict a prior in-flight job's fence from a shared BO's
>> reservation object when multiple jobs touch the same BO. Also guard
>> hwctx_fini call in amdxdna_hwctx_destroy_rcu() against NULL ops.
>
> Is this aie4 kernel submission specific? aie2 does not publish this 
> fence.
>
> If it does not fix any existing issue, please describe it clearly.

I have addressed your comments with a newer PATCH V1. This change is 
merged with KMQ patches.

It is AIE4 specific.


>
>>
>> The corresponding AIE4 command submission BO locking and fence
>> attachment logic is implemented in a subsequent patch ("accel/amdxdna:
>> Implement AIE4 command packet building and submission").
>>
>> Co-developed-by: Max Zhen <max.zhen@amd.com>
>> Signed-off-by: Max Zhen <max.zhen@amd.com>
>> Signed-off-by: David Zhang <yidong.zhang@amd.com>
>> ---
>>   drivers/accel/amdxdna/amdxdna_ctx.c | 29 ++++++++++++++++++++++-------
>>   1 file changed, 22 insertions(+), 7 deletions(-)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c 
>> b/drivers/accel/amdxdna/amdxdna_ctx.c
>> index 888e857ec558..6ca7774150d5 100644
>> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
>> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
>> @@ -25,7 +25,7 @@
>>   struct amdxdna_fence {
>>       struct dma_fence    base;
>>       spinlock_t        lock; /* for base */
>> -    struct amdxdna_hwctx    *hwctx;
>> +    struct device        *dev;
>>   };
>>     static const char *amdxdna_fence_get_driver_name(struct dma_fence 
>> *fence)
>> @@ -39,7 +39,14 @@ static const char 
>> *amdxdna_fence_get_timeline_name(struct dma_fence *fence)
>>         xdna_fence = container_of(fence, struct amdxdna_fence, base);
>>   -    return xdna_fence->hwctx->name;
>> +    /*
>> +     * Use device name rather than hwctx name: the fence is 
>> published into
>> +     * BO reservation objects via dma_resv_add_fence() and can 
>> outlive the
>> +     * hwctx (e.g. when a BO is exported as a dma-buf and imported by
>> +     * another process). The device outlives any individual context, so
>> +     * dev_name() is safe to call at any point during the fence's 
>> lifetime.
>> +     */
>> +    return dev_name(xdna_fence->dev);
>>   }
>>     static const struct dma_fence_ops fence_ops = {
>> @@ -55,9 +62,17 @@ static struct dma_fence 
>> *amdxdna_fence_create(struct amdxdna_hwctx *hwctx)
>>       if (!fence)
>>           return NULL;
>>   -    fence->hwctx = hwctx;
>> +    fence->dev = hwctx->client->xdna->ddev.dev;
>>       spin_lock_init(&fence->lock);
>> -    dma_fence_init(&fence->base, &fence_ops, &fence->lock, 
>> hwctx->id, 0);
>> +    /*
>> +     * Part of the fix to align BO reservation locking and fence
>> +     * management with AIE2: each job fence needs a unique context so
>> +     * dma_resv_add_fence() does not evict a prior job's fence from a
>> +     * shared BO's reservation object when two in-flight jobs touch
>> +     * the same BO. The corresponding AIE4 command submission locking
>> +     * and fence attachment is implemented in aie4_cmd_submit().
>> +     */
>> +    dma_fence_init(&fence->base, &fence_ops, &fence->lock, 
>> dma_fence_context_alloc(1), 0);
>>       return &fence->base;
>>   }
>>   @@ -81,13 +96,13 @@ static void 
>> amdxdna_hwctx_release_expanded_heap(struct amdxdna_hwctx *hwctx)
>>   static void amdxdna_hwctx_destroy_rcu(struct amdxdna_hwctx *hwctx,
>>                         struct srcu_struct *ss)
>>   {
>> -    struct amdxdna_client *client = hwctx->client;
>> -    struct amdxdna_dev *xdna = client->xdna;
>> +    struct amdxdna_dev *xdna = hwctx->client->xdna;
>>         synchronize_srcu(ss);
>>         /* At this point, user is not able to submit new commands */
>> -    xdna->dev_info->ops->hwctx_fini(hwctx);
>> +    if (xdna->dev_info->ops->hwctx_fini)
>> +        xdna->dev_info->ops->hwctx_fini(hwctx);
>
> This seems unrelated. Please remove from the patch.

Removed.

David

>
> Lizhi
>
>> amdxdna_hwctx_release_expanded_heap(hwctx);
>>       kfree(hwctx->name);

  reply	other threads:[~2026-09-30  0:20 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26  1:34 [PATCH V0 00/21] accel/amdxdna: Kernel submission and PM for AIE4 David Zhang
2026-09-26  1:34 ` [PATCH V0 01/21] accel/amdxdna: Rename NPU3 firmware files David Zhang
2026-09-26  1:34 ` [PATCH V0 02/21] accel/amdxdna: Remove mmap for doorbell David Zhang
2026-09-26  1:34 ` [PATCH V0 03/21] accel/amdxdna: Add CERT firmware version support David Zhang
2026-09-26  1:34 ` [PATCH V0 04/21] accel/amdxdna: Upgrade firmware version to 6.0 David Zhang
2026-09-28 17:08   ` Lizhi Hou
2026-09-26  1:34 ` [PATCH V0 05/21] accel/amdxdna: Add NPU3 classic device support David Zhang
2026-09-26  1:34 ` [PATCH V0 06/21] accel/amdxdna: Add AIE version query to aie4_get_info David Zhang
2026-09-26  1:34 ` [PATCH V0 07/21] accel/amdxdna: Add get and set power_mode for AIE4 David Zhang
2026-09-28 18:39   ` Lizhi Hou
2026-09-26  1:34 ` [PATCH V0 08/21] accel/amdxdna: Restore power mode override on AIE4 hardware start David Zhang
2026-09-28 18:48   ` Lizhi Hou
2026-09-26  1:34 ` [PATCH V0 09/21] accel/amdxdna: Add clock, DPM frequency, and resource info queries for AIE4 David Zhang
2026-09-26  1:34 ` [PATCH V0 10/21] accel/amdxdna: Add context switch hysteresis with debugfs control David Zhang
2026-09-26  1:34 ` [PATCH V0 11/21] accel/amdxdna: Refactor AIE4 hardware initialization sequence David Zhang
2026-09-26  1:34 ` [PATCH V0 12/21] accel/amdxdna: Decouple AIE4 doorbell and MSI-X notification transport hooks David Zhang
2026-09-28 20:16   ` Lizhi Hou
2026-09-26  1:34 ` [PATCH V0 13/21] accel/amdxdna: Implement AIE4 kernel queue lifecycle and memory layout David Zhang
2026-09-26  1:34 ` [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation David Zhang
2026-09-28 21:06   ` Lizhi Hou
2026-09-30  0:20     ` Zhang, Yidong (David) [this message]
2026-09-26  1:34 ` [PATCH V0 15/21] accel/amdxdna: Prepare for AIE4 command submission David Zhang
2026-09-26  1:34 ` [PATCH V0 16/21] accel/amdxdna: Implement AIE4 command packet building and submission David Zhang
2026-09-26  1:34 ` [PATCH V0 17/21] accel/amdxdna: Finalize runtime PM before acquiring dev_lock on removal David Zhang
2026-09-26  1:34 ` [PATCH V0 18/21] accel/amdxdna: Implement AIE4 suspend and resume David Zhang
2026-09-26  1:34 ` [PATCH V0 19/21] accel/amdxdna: Link SR-IOV VFs for power management sequencing David Zhang
2026-09-26  1:34 ` [PATCH V0 20/21] accel/amdxdna: Implement runtime suspend and resume support David Zhang
2026-09-26  1:34 ` [PATCH V0 21/21] accel/amdxdna: Add stub hwctx_config for AIE4 David Zhang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=906d1899-26af-4829-8a4b-9d451ff13917@amd.com \
    --to=yidong.zhang@amd.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=karol.wachowski@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lizhi.hou@amd.com \
    --cc=mario.limonciello@amd.com \
    --cc=max.zhen@amd.com \
    --cc=ogabbay@kernel.org \
    --cc=quic_jhugo@quicinc.com \
    --cc=sonal.santan@amd.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®